7.5
CVE-2019-19942
- EPSS 0.28%
- Veröffentlicht 16.03.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 04:35:42
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Missing output sanitation in Swisscom Centro Grande Centro Grande before 6.16.12, Centro Business 1.0 (ADB) before 7.10.18, and Centro Business 2.0 before 8.02.04 allows a remote attacker to perform DNS spoofing against the web interface via crafted hostnames in DHCP requests.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Swisscom ≫ Centro Grande Firmware Version < 6.14.06
Swisscom ≫ Centro Business Version >= 1.0 < 7.10.18
Swisscom ≫ Centro Business Version >= 2.0 < 8.02.04
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.48 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.